{"id":1571538,"url":"https://alion.io/job/scor-application-security-architect","title":"Application Security Architect","company":{"id":1816594,"name":"SCOR","domain":"scor.com","url":"https://alion.io/company/scor-com","size_band":"1001-5000","is_staffing_agency":false,"employer_type":"direct","is_intermediary":false,"listed_via":null,"ats_vendor":"Oracle","truth_index":null},"role":"Security","role_family":"Security","seniority":"staff","employment_type":null,"work_mode":"hybrid","remote_scope":null,"remote_scope_basis":null,"remote_working_hours":null,"hiring_geo_confidence":"structured","locations":["Bucharest, Romania"],"countries":["RO"],"hiring_countries":[],"hiring_countries_total":0,"salary":null,"salary_estimate":{"min_usd":40000,"max_usd":93000,"period":"year","method":"global_role_cell_scaled_by_country","sample_n":415},"experience_years_min":5,"visa_sponsorship":false,"relocation_package":false,"has_equity":false,"technologies":[{"name":"Agile","optional":false},{"name":"AWS","optional":false},{"name":"Azure","optional":false},{"name":"CI/CD","optional":false},{"name":"GCP","optional":false},{"name":"IAM","optional":false},{"name":"OWASP","optional":false},{"name":"OWASP ASVS","optional":false},{"name":"OWASP SAMM","optional":false},{"name":"PowerShell","optional":false},{"name":"Threat Modeling","optional":false},{"name":"Windows","optional":false}],"status":"live","first_seen_at":"2026-07-31T06:37:03Z","employer_posted_date":"2026-07-31","last_verified_at":"2026-10-01T13:58:59Z","board_verified":true,"closed_at":null,"days_open":62,"trust":{"level":"ok","repost_count":null,"flags":[],"days_open":62},"description":"We are seeking an Application Security Architect to join our Security team and lead the design and implementation of secure software solutions across the organization. The ideal candidate is proactive, technically adept, and deeply knowledgeable in secure software development practices. You will collaborate closely with development teams to embed security into the software lifecycle from the ground up, ensuring robust protection of sensitive data and systems.\nThis role involves conducting security assessments, defining application security requirements, and promoting secure coding standards. You will also stay ahead of emerging threats and vulnerabilities, applying this intelligence to continuously strengthen the organization’s application security posture. Your expertise will be critical in safeguarding the confidentiality, integrity, and availability of our applications.\n Key duties and responsibilities\nAs an Application Security Architect, you will be responsible for designing and implementing secure software solutions across SCOR’s IT landscape. You will collaborate with development and IT teams to embed security into the software development lifecycle (SDLC), define and enforce secure coding practices, and ensure compliance with SCOR’s internal control and security standards. You will also monitor emerging threats and vulnerabilities, and proactively adapt security measures to maintain the confidentiality, integrity, and availability of SCOR’s business applications.\nKey Responsibilities:\n\nSecurity Architecture Standards: Develop and maintain security architecture standards for cloud infrastructures, APIs, and applications, and promote their adoption across IT functional teams\n\nSecure SDLC Integration: Participate in the review and definition of the software development and SaaS integration lifecycle, aligning with SCOR’s internal control and OWASP-based best practices (e.g., SAMM, ASVS, Top 10 proactive controls, STG, Cheat Sheet Series)\n\nOperational Security Practices: Define and maintain standard operational security practices across application environments.\n\nNetwork Security Advocacy: Promote and drive adoption of network security practices throughout the enterprise.\nSecurity Metrics and Dashboards: Develop and maintain dashboards to track program maturity, incidents, and operational effectiveness.\nSecurity Configuration Management: Define and enforce standard security configurations for technical solutions to ensure availability, integrity, data protection, and privacy.\nSecurity Assessmen t and Enhancement: Review current security measures on business applications and recommend enhancements based on evolving standards.\nAudit Remediation Support: Assist IT teams in implementing remediation plans for security findings identified during audits.\nKey Duties:\nDesign and enforce secure architecture standards for cloud and application environments.\nIntegrate security into the software development lifecycle using OWASP-aligned frameworks.\nMaintain and promote operational and network security practices.\nMonitor and report on application security posture using metrics and dashboards.\nReview and enhance security configurations and controls for business applications.\nSupport remediation efforts for audit findings and ensure compliance with SCOR’s security policies.\nRequired experience & competencies\nMust adhere to our Key Security Principles and Team Values:\nSecurity Principles: Defend the business, support the business, and promote responsible information security behavior.\nTeam Values: Professionalism, Ethics, Transparency, and Team Spirit.\nHard skills\nMinimum 5-10 years of overall IT experience, with at least 3 years in a dedicated Application Security, Security Architecture, or Secure Software Engineering role in complex enterprise environments.\n\nProven experience designing and enforcing application security architectures for business-critical and regulated systems, covering on-premise, cloud, and hybrid environments.\n\nHands-on experience embedding security into the SDLC across multiple delivery models (Agile, DevSecOps, SaaS integration), including security gates, threat modeling, and architecture reviews.\n\nDemonstrated experience working with development teams as a security authority and trusted advisor, not only as a reviewer or auditor.\n\nPrior exposure to audit, regulatory, or internal control environments, with a track record of supporting remediation and demonstrating security-by-design.\n\nStrong hands-on experience securing cloud-based applications\n\nExperience integrating security into CI/CD pipelines, including: SAST, DAST, SCA, and dependency scanning\nSolid understanding of modern authentication and identity federation mechanisms (OIDC, OAuth2, SAML), and their application in enterprise and SaaS contexts.\nGood understanding of networking fundamentals and security controls (protocols, proxies, firewalls, WAFs, segmentation).\nStrong knowledge of enterprise IAM and identity platforms (hybrid IdP, IAM, MDM), and their impact on application security design.\nScripting and automation capability (PowerShell and/or equivalent) to support security assessments, controls, or integrations.\nWorking knowledge of Windows and cross-platform environments, including security services and policy enforcement.\nDemonstrated ability to translate security principles into enforceable requirements aligned with internal control frameworks and policies.\nSoft skills\nStrong analytical and problem-solving skills.\n\nEffective communication and collaboration abilities.\n\nAbility to work independently and in cross-functional teams.\n\nAttention to detail and a proactive mindset.\n\nRequired Education\nMaster’s degree in Computer Science, Cybersecurity, or a closely related field (mandatory).\n\nRelevant security certifications strongly preferred, such as:\nCSSLP\n\nCISSP (or ISSAP)\n\nCCSP\n\nGIAC Application Security certifications\n\nCloud security certifications (Azure / AWS / GCP)","description_format":"text","description_chars":5953,"description_truncated":false,"requirements":{"experience_years_min":5,"management_years_min":null,"team_size_min":null,"manages_managers":false,"education":{"level":"master","optional":false},"security_clearance":false,"languages":[]},"benefits":[],"hiring_locations":[],"hiring_excludes":[],"relocation_offered":false,"industries":["Application Security","Bakery & Pastry","Reinsurance"],"lifecycle":[{"event":"open","at":"2026-10-01T08:00:07Z"}],"liveness":{"score":20,"band":"cold","label":"Long shot","p_open":1,"p_active":0.568,"p_room":0.36,"age_days":62,"expected_fill_days":38,"reasons":["conf:10","win:tail","crowd:brand"],"computed_at":"2026-10-02T00:21:56Z"},"pay":null,"html_url":"https://alion.io/job/scor-application-security-architect","json_url":"https://alion.io/job/scor-application-security-architect.json","meta":{"generated_at":"2026-10-02T00:21:56Z","cache_seconds":300,"methodology":"https://alion.io/methodology","terms":"https://alion.io/terms","contact":"https://alion.io/contact","api":"https://alion.io/developers","usage":{"tier":"crawler","counted_by":"address","units_charged":1,"used_today":205,"day_limit":5000,"remaining_today":4795,"minute_limit":60,"resets_at":"2026-10-03T00:00:00Z"}}}